|
| |||
![]() |
|||
|
|
Preventing Identity Theft: What You Need to DoBy Samuel A. Collins Q: I understand that there are some new rules regarding identity theft that will be implemented this year. Is there something I must do to comply with these rules or am I exempt because I am an chiropractor and most of my patients pay cash? A: You are correct that there will be further implementation of HIPAA regulations, under the direction of the Federal Trade Commission, to protect patient privacy of their health information. Specifically, this new rule, referred to as the "red flags" rule, covers identity theft. Providers of health care services must implement a protocol to prevent identity theft and identify patterns or practices that may indicate potential identity theft. [To learn more about the rule, implementation of which has been delayed until later this year, read "Are You Ready for the Red Flags Rule?" in the July 1 issue of DC.] Essentially, the rule is designed to prevent someone from using another person's name or identifying information to submit invoices, statements, bills, insurance billing or for other purposes consistent with collection and reimbursement of health care services. Therefore, any provider who bills for services, even simple cash transactions, will need to follow the new regulations to prevent identity theft. It has been misconstrued that privacy regulations do not apply if you do not bill insurance or bill electronically. In fact, privacy rules do apply to all providers - all patients have a right to the privacy of their medical information, so all health care providers have a duty to ensure the protection of that information. However, the level of standards and procedures required in each office can vary greatly. Certainly if you are not doing electronic billing, the privacy regulations pertaining to electronic data need not be followed. However, just because you may not do that particular type of billing does not exempt you from the overall rules of privacy. Don't feel intimidated by this. It simply requires that you have a written protocol outlining what your office does to recognize and prevent identity theft; more specifically medical identity theft. The following is a simple format for a document of compliance that could be titled "Detecting Red Flags of Identity Theft." This example is for a small health care practice with a well-known, limited patient base and a low, minimal or nonexistent risk of identity theft. The following procedures should be followed to identify red flags:
The above is essentially all that is needed, as it serves as a written protocol for compliance with the new regulation. For the most part, this is likely something you were already doing as part of your practice; now you are documenting the protocol in writing. If you'd like more information, I will send a complete compliance document for this regulation that includes more detail, as well as specific follow-up protocols when there may be a discrepancy. Please contact me at and request the "identity theft" document in the subject line. Click here for more information about Samuel A. Collins.
|
|
|
|
||